Trace status codes and Location headers to identify the rule that closes the loop. Check opposing rules involving hostnames, HTTP and HTTPS, trailing slashes or login paths.
Cloudflare Flexible connects to the origin over HTTP. A redirect from that origin back to HTTPS can create a loop. Simply enabling Always Use HTTPS alongside an origin HTTP-to-HTTPS redirect does not inherently create one.
After locating the conflict, make TLS connections and redirect rules consistent. Recheck final responses and internal links, then monitor Search Console and logs for recovery. Impact depends on scope, duration and recrawling, among other factors.
